CVE-2023-24035
Awaiting Analysis Awaiting Analysis - Queue

Timing Attack in Nagios XI Authentication

Vulnerability report for CVE-2023-24035, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-22

Assigner: MITRE

Description

An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-22
Generated
2026-10-04
AI Q&A
2026-09-14
EPSS Evaluated
2026-10-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nagios nagios_xi to 5.9.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-208 Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Nagios XI versions before 5.9.3. It involves a timing attack due to an insecure comparison in the is_insecure_login_authenticated function. An attacker can exploit this by measuring timing differences during password authentication to brute force the admin password.

Detection Guidance

This vulnerability involves a timing attack on Nagios XI's admin password authentication before version 5.9.3. To detect it, check your Nagios XI version using the web interface or command line. If you are running a version older than 5.9.3, the system is vulnerable. No specific commands are provided in the context to actively detect the vulnerability on your network.

Impact Analysis

An attacker could gain unauthorized access to the Nagios XI admin account by brute forcing the password. This could allow them to view sensitive system information, modify configurations, or disrupt services.

Compliance Impact

This vulnerability allows brute-forcing admin passwords through timing attacks, which could lead to unauthorized access to sensitive data. This may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data security) by enabling unauthorized access to personal or health information.

Mitigation Strategies

Upgrade Nagios XI to version 5.9.3 or later to address the insecure timing comparison vulnerability in the admin password authentication process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-24035. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart